An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
References
Link | Resource |
---|---|
https://github.com/dart-lang/http/issues/511 | Exploit Patch Third Party Advisory |
https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133 | Broken Link Release Notes Third Party Advisory |
Configurations
Information
Published : 2020-12-23 19:15
Updated : 2022-07-19 04:02
NVD link : CVE-2020-35669
Mitre link : CVE-2020-35669
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
dart
- http